Information Security Risk Analyst

The Cheesecake FactoryAgoura Hills, CA
1d$123,000 - $134,000Hybrid

About The Position

As an Information Security Risk Analyst reporting to the Information Security Manager, you’ll be at the center of enterprise risk, compliance, and third-party oversight. This role is instrumental in building scalable security and governance processes that support growth, enhance resilience, and enable teams across the organization to move faster with confidence. You’ll thrive in this role if you are: Stakeholder Savvy: You work confidently with auditors and senior leaders, communicating with clarity and professionalism that strengthens collaboration and drives alignment. Precision Driven: You thrive in structured environments, bringing a process minded approach that ensures accurate, consistent, and high quality work every time. Business Focused Translator: You turn complex security and risk concepts into clear business insights, helping leaders make informed, practical decisions with confidence. Governance Minded: You’re energized by policy, structure, and accountability—preferring governance, compliance, and risk work over hands on security engineering.

Requirements

  • 3+ years of experience in Governance, Risk & Compliance, IT Audit, or Security Risk
  • Hands-on experience with at least one framework: PCI DSS, SOX, or NIST
  • Working knowledge of identity governance concepts
  • Strong analytical, documentation, and communication skills

Nice To Haves

  • Experience with TPRM programs or GRC platforms
  • Exposure to public accounting, consulting, or regulated enterprises
  • Relevant certifications (CISA, CISSP, ISO 27001) a plus

Responsibilities

  • Lead and support audits including PCI DSS, SOX, and NIST CSF
  • Coordinate evidence collection, control testing, and remediation tracking
  • Maintain and enhance security policies, procedures, and audit documentation
  • Partner with Internal Audit and Accounting on annual and quarterly audit requirements
  • Own the end-to-end third-party risk lifecycle
  • Perform security assessments for new and existing vendors
  • Partner with Legal, Procurement, and business teams on vendor risk decisions
  • Develop risk scoring, reporting, and ongoing monitoring processes
  • Review and analyze Active Directory and Entra ID access reports
  • Support SOX access reviews and privilege validation
  • Identify access anomalies and partner with IT/Security for remediation
  • Ensure access changes follow approval and ticketing workflows
  • Produce risk assessment and audit reports for leadership
  • Assist with automating recurring audit and compliance reporting
  • Track control failures, root causes, and remediation plans

Benefits

  • Vacation and sick time
  • Medical, Dental & Vision
  • 401K with company match
  • Tuition Reimbursement
  • 25%-35% discount when dining as a guest
  • Annual stipend for dining in our restaurants
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service